Impact
A security flaw in the Tenda CP3 firmware (27.5.57.101) allows an attacker to remotely inject operating‑system commands by manipulating the AlarmVoiceURL argument in the SystemAsh function within Apis/system.c. This injection can execute arbitrary commands with the privileges of the device, leading to full system compromise, data exfiltration, or disruption of network services.
Affected Systems
The vulnerable vendor is Tenda, specifically the CP3 router series. The flaw exists in firmware version 27.5.57.101; it is not confirmed whether other firmware builds of the CP3 are affected.
Risk and Exploitability
The CVSS score of 9.4 marks this as a critical vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, so current exploitation evidence is unknown. The flaw is exploitable remotely through the device’s API, implying that an attacker who can reach the router could gain full control. The lack of public exploit data does not diminish the inherent risk posed by the high severity and remote attack vector.
OpenCVE Enrichment